Erez Pasternak wrote:
> Hi
>
> Does anyone here knows
>
> 1) Which versions of Open SSL are FIPS 140-2 certified on Linux?
> Which versions of Linux?
>
> 2) Which versions of Open SSL are FIPS 140-2 certified on
> Windows? Which versions of Windows?
>
> Thanks
>
> Erez Pasternak


There is currently only one validated version of the OpenSSL FIPS Object
Module, v1.1.2 with certificate #918:
http://csrc.nist.gov/groups/STM/cmvp...al-all.htm#918.

Note it's "validation", not "certification". Also please note that
OpenSSL itself (the distro we all know and love) is not and presumably
never will be FIPS 140-2 validated. The OpenSSL FIPS Object Module is a
separate distinct software component derived from, and designed to
interoperate with, OpenSSL proper.

The v1.1.2 module supports Linux/Unix and Windows (most versions, sort
of), but without assembler optimizations. It is based on and compatible
with OpenSSL 0.9.7+.

I'm expecting two more validations for the 0.9.8+ based v1.2 Real Soon Now.

-Steve M.

--
Steve Marquess
Open Source Software Institute
marquess@oss-institute.org

__________________________________________________ ____________________
OpenSSL Project http://www.openssl.org
Development Mailing List openssl-dev@openssl.org
Automated List Manager majordomo@openssl.org